#!/bin/bash
#封禁的思路参考auto_deny_ip.sh文件
#TCP的80端口连接数 
TCP_connection_num=1   
rpm -q net-tools &>/dev/null
if [ $? -ne 0 ]; then
    yum -y install net-tools
fi

ABNORMAL_IP=$(netstat -an | awk  '$4~/:80$/&&$6~/ESTABLISHED/{gsub(/:[0-9]+/,"",$5);{a[$5]++}}END{for(i in a)if(a[i]>=TCP_connection_num)print i}')

for IP in $ABNORMAL_IP; do
    if [ $(iptables -vnL | grep -c "$IP") -eq 0 ]; then
       # iptables -I INPUT -s $IP -j DROP
       echo $IP
    fi
done